A command injection vulnerability in the telnet service of Adtran 411 ONT L80.00.0011.M2 allows attackers to escalate privileges to root and execute arbitrary commands.
                
            References
                    | Link | Resource | 
|---|---|
| https://drive.google.com/file/d/1levaZk5aC6g6a2zPW8xlOIVAu9MFYvAz/view | Third Party Advisory | 
| https://lanrat.com/posts/adtran-isp-hacking/ | |
| https://www.youtube.com/watch?v=Aic-QaSqjxc | Exploit | 
| https://drive.google.com/file/d/1levaZk5aC6g6a2zPW8xlOIVAu9MFYvAz/view | Third Party Advisory | 
Configurations
                    Configuration 1 (hide)
| AND | 
 
 | 
History
                    18 Aug 2025, 17:15
| Type | Values Removed | Values Added | 
|---|---|---|
| References | 
 | 
12 Jun 2025, 20:50
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time | Adtran 411 Adtran Adtran 411 Firmware | |
| References | () https://drive.google.com/file/d/1levaZk5aC6g6a2zPW8xlOIVAu9MFYvAz/view - Third Party Advisory | |
| References | () https://www.youtube.com/watch?v=Aic-QaSqjxc - Exploit | |
| Summary | 
 | |
| CPE | cpe:2.3:o:adtran:411_firmware:l80.00.0011.m2:*:*:*:*:*:*:* cpe:2.3:h:adtran:411:-:*:*:*:*:*:*:* | 
01 Apr 2025, 15:16
| Type | Values Removed | Values Added | 
|---|---|---|
| References | () https://drive.google.com/file/d/1levaZk5aC6g6a2zPW8xlOIVAu9MFYvAz/view - | |
| CWE | CWE-77 | |
| CVSS | v2 : v3 : | v2 : unknown v3 : 9.8 | 
31 Mar 2025, 15:15
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2025-03-31 15:15
Updated : 2025-08-18 17:15
NVD link : CVE-2025-22939
Mitre link : CVE-2025-22939
CVE.ORG link : CVE-2025-22939
JSON object : View
Products Affected
                adtran
- 411_firmware
- 411
CWE
                
                    
                        
                        CWE-77
                        
            Improper Neutralization of Special Elements used in a Command ('Command Injection')
